Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

feat(providers): support multiple dynamic credential injections on one request

Đang mở
#3,320 8 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
rust
Lĩnh vực
api, authentication, security

Hướng nghiên cứu

Bắt đầu bằng việc xác định các điểm vào để khớp endpoint của provider, phân giải động việc cấp token và chèn header gửi đi; issue không nêu tên file hay test nào. Sử dụng các tiêu chí chấp nhận để xác định phạm vi bao phủ cho các lượt cấp độc lập, tính nguyên tử khi xảy ra lỗi, xung đột, redaction, caching và isolation; hoàn tất nghĩa là tất cả các hành vi bảo mật và đồng thời được liệt kê đều đã được xác minh.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area:providers area:supervisor state:accepted topic:l7

Summary

Support multiple independently resolved dynamic credential injections on one matching outbound HTTP request, including a SPIFFE JWT-SVID in a configured custom header and an independent Authorization: Bearer access token.

Problem

The POC has an outbound route where two separate security layers protect the same request:

  1. An identity-aware proxy or service requires a dynamically obtained SPIFFE JWT-SVID in a configured custom header.
  2. The destination service requires a separately acquired short-lived bearer access token in Authorization.

Providers v2 can describe bearer or custom-header placement for a dynamic token grant, but the provider/request contract needs to support composing multiple dynamic credentials for the same endpoint without materializing either token in the agent environment or adding an application-side proxy.

This is not a request to duplicate one token into arbitrary headers. Each injection has its own issuer, audience, scopes, cache lifetime, and failure semantics.

Requested behavior

  • Allow a provider endpoint to reference multiple dynamic token-grant credentials for one request.
  • Resolve and inject each credential only after endpoint and L7 policy admission.
  • Support at least:
    • injection of a SPIFFE JWT-SVID into a provider-configured custom header for Teleport-based or other SPIFFE-compatible services;
    • an independently resolved Authorization: Bearer <token> credential for the destination service.
  • Keep grant configuration independent per credential: token endpoint, JWT-SVID audience, resource audience, scopes, header placement, and cache TTL.
  • Define deterministic conflict behavior when the agent supplies either protected header. The default should replace or reject according to explicit provider policy, never silently forward an untrusted agent value.
  • Resolve all required credentials before forwarding; if any grant fails, inject none and fail closed.
  • Redact both credentials from agent-visible state, logs, traces, errors, and policy events.

Acceptance criteria

  • One HTTPS request matching a provider endpoint can receive both a SPIFFE JWT-SVID in a provider-configured custom header and an independently acquired bearer token.
  • The two grants may use different token endpoints, audiences, scopes, and cache expiration times.
  • Actual credential values and reusable credential handles are never exposed to the sandbox or agent. A non-secret opaque placeholder may be visible to the agent, provided credential substitution remains endpoint-scoped and enforced by the Supervisor.
  • Header injection occurs only for the matched scheme, host, port, and path and only when TLS inspection is active.
  • A failure in either grant prevents the upstream request and does not leave a partially injected request.
  • Concurrent requests do not mix credentials across sandbox, provider instance, subject, audience, or endpoint.
  • Tests cover cache hit/expiry, independent refresh, agent-supplied header conflicts, one-grant failure, redaction, and cross-sandbox isolation.

Example use case

Agent -> OpenShell Supervisor -> identity-aware proxy -> destination service

The Supervisor performs last-mile injection of:

  1. A SPIFFE JWT-SVID required by the identity-aware proxy.
  2. A separate short-lived bearer token required by the destination service.

The two credentials may have different issuers, audiences, scopes, token endpoints, and expiration times. Neither credential is exposed to the agent.

Ngôn ngữ chính
Rust
Star
13.2k
Fork
1.6k
Merge trung bình
1 ngày 23 giờ
Pull request đã merge (30 ngày)
355

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của NVIDIA/OpenShell

Tất cả issue của NVIDIA/OpenShell

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.